From 7d380f9b43e98031aa42a9125829cf16916b773d Mon Sep 17 00:00:00 2001
From: Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com>
Date: Wed, 19 Jun 2024 19:34:12 +0200
Subject: [PATCH] fix: documentation improvements
---
docs/cli/commands/login.mdx | 169 +++++++++++++++++++++++++++++++++++-
1 file changed, 168 insertions(+), 1 deletion(-)
diff --git a/docs/cli/commands/login.mdx b/docs/cli/commands/login.mdx
index 636e5672c..9e011324f 100644
--- a/docs/cli/commands/login.mdx
+++ b/docs/cli/commands/login.mdx
@@ -7,7 +7,7 @@ description: "Login into Infisical from the CLI"
infisical login
```
-## Description
+### Description
The CLI uses authentication to verify your identity. When you enter the correct email and password for your account, a token is generated and saved in your system Keyring to allow you to make future interactions with the CLI.
To change where the login credentials are stored, visit the [vaults command](./vault).
@@ -23,6 +23,9 @@ If you have added multiple users, you can switch between the users by using the
### Flags
+The login command supports a number of flags that you can use for different authentication methods. Below is a list of all the flags that can be used with the login command.
+
+
```bash
infisical login --method= # Optional, will default to 'user'.
@@ -98,8 +101,172 @@ If you have added multiple users, you can switch between the users by using the
The `service-account-key-path` flag can be substituted with the `INFISICAL_GCP_IAM_SERVICE_ACCOUNT_KEY_FILE_PATH` environment variable.
+
+### Authentication Methods
+
+The Infisical CLI supports multiple authentication methods. Below are the available authentication methods, with their respective flags.
+
+
+
+ The Universal Auth method is a simple and secure way to authenticate with Infisical. It requires a client ID and a client secret to authenticate with Infisical.
+
+
+
+
+ Your machine identity client ID.
+
+
+ Your machine identity client secret.
+
+
+
+
+
+
+ To create a universal auth machine identity, follow the step by step guide outlined [here](/documentation/platform/identities/universal-auth).
+
+
+ Run the `login` command with the following flags to obtain an access token:
+
+ ```bash
+ infisical login --method=universal-auth --client-id= --client-secret=
+ ```
+
+
+
+
+ The Native Kubernetes method is used to authenticate with Infisical when running in a Kubernetes environment. It requires a service account token to authenticate with Infisical.
+
+
+
+
+ Your machine identity ID.
+
+
+ Path to the Kubernetes service account token to use. Default: `/var/run/secrets/kubernetes.io/serviceaccount/token`.
+
+
+
+
+
+
+ To create a Kubernetes machine identity, follow the step by step guide outlined [here](/documentation/platform/identities/kubernetes-auth).
+
+
+ Run the `login` command with the following flags to obtain an access token:
+
+ ```bash
+ # --service-account-token-path is optional, and will default to '/var/run/secrets/kubernetes.io/serviceaccount/token' if not provided.
+ infisical login --method=kubernetes --machine-identity-id= --service-account-token-path=
+ ```
+
+
+
+
+
+ The Native Azure method is used to authenticate with Infisical when running in an Azure environment.
+
+
+
+
+ Your machine identity ID.
+
+
+
+
+
+
+ To create an Azure machine identity, follow the step by step guide outlined [here](/documentation/platform/identities/azure-auth).
+
+
+ Run the `login` command with the following flags to obtain an access token:
+
+ ```bash
+ infisical login --method=azure --machine-identity-id=
+ ```
+
+
+
+
+
+ The Native GCP ID Token method is used to authenticate with Infisical when running in a GCP environment.
+
+
+
+
+ Your machine identity ID.
+
+
+
+
+
+
+ To create a GCP machine identity, follow the step by step guide outlined [here](/documentation/platform/identities/gcp-auth).
+
+
+ Run the `login` command with the following flags to obtain an access token:
+
+ ```bash
+ infisical login --method=gcp-id-token --machine-identity-id=
+ ```
+
+
+
+
+ The GCP IAM method is used to authenticate with Infisical with a GCP service account key.
+
+
+
+
+ Your machine identity ID.
+
+
+ Path to your GCP service account key file _(Must be in JSON format!)_
+
+
+
+
+
+
+ To create a GCP machine identity, follow the step by step guide outlined [here](/documentation/platform/identities/gcp-auth).
+
+
+ Run the `login` command with the following flags to obtain an access token:
+
+ ```bash
+ infisical login --method=gcp-iam --machine-identity-id= --service-account-key-file-path=
+ ```
+
+
+
+
+ The AWS IAM method is used to authenticate with Infisical with an AWS IAM role while running in an AWS environment like EC2, Lambda, etc.
+
+
+
+
+ Your machine identity ID.
+
+
+
+
+
+
+ To create an AWS machine identity, follow the step by step guide outlined [here](/documentation/platform/identities/aws-auth).
+
+
+ Run the `login` command with the following flags to obtain an access token:
+
+ ```bash
+ infisical login --method=aws-iam --machine-identity-id=
+ ```
+
+
+
+
+
### Machine Identity Authentication Quick Start
In this example we'll be using the `universal-auth` method to login to obtain an Infisical access token, which we will then use to fetch secrets with.